Drupal Security Team's Avatar

Drupal Security Team

@drupalsecurity

Automatically post Drupal Security Advisories & related news. Follow Drupal Security Team. @gknaddison.bsky.social to get RT. DM & mentions not monitored. https://drupal.org/node/101494

712
Followers
2
Following
172
Posts
20.09.2023
Joined
Posts Following

Latest posts by Drupal Security Team @drupalsecurity

Preview
Home Drupal is an open source platform for building amazing digital experiences. It's made by a dedicated community. Anyone can use it, and it will always be free.

There is a delay in delivering emails announcing today's advisories due to the drupal.org data center migration. See drupal.community/@drupalinfra... for more details.

04.03.2026 18:09 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027 Read post

04.03.2026 18:04 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Google Analytics GA4 - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-024 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020 Read post

04.03.2026 18:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Drupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-017 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Islandora - Moderately critical - Arbitrary file upload, Cross-site scripting - SA-CONTRIB-2026-016 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

CAPTCHA - Moderately critical - Access bypass - SA-CONTRIB-2026-015 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Material Icons - Moderately critical - Access bypass - SA-CONTRIB-2026-011 Read post

25.02.2026 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

UI Icons - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-010 Read post

11.02.2026 17:27 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009 Read post

11.02.2026 17:27 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008 Read post

04.02.2026 17:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007 Read post

28.01.2026 17:36 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006 Read post

28.01.2026 17:36 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Drupal 25th Anniversary Timeline | Drupal 25th Anniversary Timeline Celebrating 25 years of Drupal - A timeline of innovation and community

Happy 25th anniversary to Drupal. I build it w/ many of you & loved every minute. In honor, I present weitzman.github.io/drupal25-tim...

@klau.si @gknaddison.bsky.social @walkah.social @ksenzee.bsky.social @outlandishjosh.bsky.social @webchick.bsky.social @quicksketch.org @merlinofchaos.bsky.social

15.01.2026 13:34 ๐Ÿ‘ 16 ๐Ÿ” 6 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1

Happy anniversary! From the timeline on August 1, 2005:

Drupal security team is formed

This volunteer team is first led by chx. The team dutifully protects Drupal core and all the contrib modules that opt into its coverage. Future leaders would be Heine, greggles, and mlhess.

15.01.2026 14:52 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

Microsoft Entra ID SSO Login - Critical - Access bypass - SA-CONTRIB-2026-005 Read post

14.01.2026 18:15 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

AT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-004 Read post

14.01.2026 18:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003 Read post

14.01.2026 18:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002 Read post

14.01.2026 18:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Group invite - Moderately critical - Access bypass - SA-CONTRIB-2026-001 Read post

14.01.2026 18:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0